Last Updated: Monday, June 1, 2026 2:39 PM
What’s Happening
Oracle has begun releasing Critical Security Patch Updates (CSPU). They released the first on Thursday, May 28th, 2026. They have outlined a subsequent monthly schedule as follows:
- 16 June 2026
- 18 August 2026
- 15 September 2026
- 17 November 2026
The CVE list from Oracle’s May 28th Critical Security Patch Update includes several high severity vulnerabilities. It is not yet known if they are EITW. We strongly recommend identifying any Oracle products in your network and patching them ASAP. The following are the Risk Matrices, split up by product, provided by Oracle in their CSPU.
Oracle Database Server Vulnerabilities:
| CVE ID | Component | Package and/or Privilege Required | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes |
|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req’d |
User Interact |
Scope | Confid- entiality |
Inte- grity |
| CVE-2026-46833 | Net Service | None | TLS | Yes | 9.0 | Network | High | None | None | Changed | High | High | High | 23.4.0-23.26.2 | See Note 1 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-46834 | Net Service | None | TLS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 23.4.0-23.26.2 | See Note 1 |
| CVE-2026-46835 | Net Service | None | TLS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 23.4.0-23.26.2 | See Note 1 |
The Net Service vulnerabilities can effect Oracle Homes, Oracle Database, Oracle Grid, and Oracle Client.
Oracle REST Data Services Vulnerabilities:
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes |
|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req’d |
User Interact |
Scope | Confid- entiality |
Inte- grity |
| CVE-2026-46840 | Oracle REST Data Services | Backend-as-a-Service | HTTPS | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 24.2.0-26.1.0 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-46775 | Oracle REST Data Services | Core | HTTPS | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 24.2.0-26.1.0 | |
| CVE-2026-46839 | Oracle REST Data Services | Core | HTTPS | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 24.2.0-26.1.0 | |
| CVE-2026-2332 | Oracle REST Data Services | Core (Eclipse Jetty) | HTTPS | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 24.2.0-26.1.0 | |
| CVE-2026-35277 | Oracle REST Data Services | Core | HTTPS | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 24.2.0-26.1.0 | |
| CVE-2026-35266 | Oracle REST Data Services | Core | HTTPS | No | 7.9 | Network | High | Low | Required | Changed | High | High | Low | 24.2.0-26.1.0 | |
| CVE-2026-46829 | Oracle REST Data Services | Mongoapi | HTTPS | Yes | 7.5 | Network | Low | None | None | Un- changed |
None | None | High | 24.2.0-26.1.0 | |
| CVE-2026-46842 | Oracle REST Data Services | Core | HTTPS | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | Low | None | 24.2.0-26.1.0 | |
| CVE-2026-46843 | Oracle REST Data Services | Core | HTTPS | Yes | 5.3 | Network | Low | None | None | Un- changed |
None | None | Low | 24.2.0-26.1.0 | |
| CVE-2026-46841 | Oracle REST Data Services | General | HTTPS | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 24.2.0-26.1.0 | |
| CVE-2026-46830 | Oracle REST Data Services | Mongoapi | HTTPS | Yes | 5.3 | Network | Low | None | None | Un- changed |
Low | None | None | 24.2.0-26.1.0 |
- The patch for CVE-2026-2332 also addresses CVE-2026-5795.
Additional patches included for non-exploitable CVEs:
- Oracle REST Data Services
- Core (Lodash): CVE-2026-4800, CVE-2025-13465 and CVE-2026-2950 [VEX Justification: vulnerable_code_not_in_execute_path].
Oracle Communications Vulnerabilities:
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes |
|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req’d |
User Interact |
Scope | Confid- entiality |
Inte- grity |
| CVE-2026-33557 | Oracle Communications Unified Assurance | Message Bus (Apache Kafka) | TCP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 6.1.1-7.0.0 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2025-15467 | Oracle Communications Unified Assurance | Core (MySQL Server) | HTTP | Yes | 8.8 | Network | Low | None | Required | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-41044 | Oracle Communications Unified Assurance | Message Bus (Apache ActiveMQ) | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2025-58050 | Oracle Communications Unified Assurance | Core (PCRE2) | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | None | High | 6.1.1-7.0.0 | |
| CVE-2026-34487 | Oracle Communications Unified Assurance | Core (Apache Tomcat) | HTTP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 6.1.1-7.0.0 | |
| CVE-2026-24308 | Oracle Communications Unified Assurance | Core (Apache ZooKeeper) | TCP | Yes | 7.5 | Network | Low | None | None | Un- changed |
High | None | None | 6.1.1-7.0.0 | |
| CVE-2026-25646 | Oracle Communications Unified Assurance | Core (libpng) | HTTP | No | 6.4 | Network | High | High | Required | Un- changed |
High | High | High | 6.1.1-7.0.0 | |
| CVE-2026-34059 | Oracle Communications Unified Assurance | Core (Apache HTTP Server) | HTTP | No | 4.5 | Network | Low | High | Required | Un- changed |
High | None | None | 6.1.1-7.0.0 |
- The patch for CVE-2026-41044 also addresses CVE-2026-40466 and CVE-2026-41043.
- The patch for CVE-2025-15467 also addresses CVE-2025-14017, CVE-2026-21998, CVE-2026-22001, CVE-2026-22002, CVE-2026-22004, CVE-2026-22005, CVE-2026-22009, CVE-2026-22015, CVE-2026-22017, CVE-2026-34270, CVE-2026-34271, CVE-2026-34276, CVE-2026-34303, CVE-2026-34304, CVE-2026-34308, CVE-2026-35236, CVE-2026-35237, CVE-2026-35238, CVE-2026-35239, and CVE-2026-35240.
- The patch for CVE-2026-33557 also addresses CVE-2026-35554.
- The patch for CVE-2026-34059 also addresses CVE-2026-23918, CVE-2026-24072, CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, and CVE-2026-34032.
- The patch for CVE-2026-24308 also addresses CVE-2026-24281.
- The patch for CVE-2026-34487 also addresses CVE-2026-29145, CVE-2026-34483, CVE-2026-34486, and CVE-2026-34500.
Oracle E-Business Suite Vulnerabilities:
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes |
|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req’d |
User Interact |
Scope | Confid- entiality |
Inte- grity |
| CVE-2026-46822 | Oracle iAssets | Internal Operations | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.3-12.2.15 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-46824 | Oracle Universal Work Queue | Work Provider Site Level Administration | HTTP | No | 9.9 | Network | Low | Low | None | Changed | High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-46817 | Oracle Payments | File Transmission | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-46819 | Oracle Internet Procurement Connector | Internal Operations | HTTP | Yes | 9.1 | Network | Low | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-46837 | Oracle Flow Manufacturing | Security | SQL | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.9-12.2.15 | |
| CVE-2026-46827 | Oracle Payroll | Self Service Manager | HTTP | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-46826 | Oracle Payroll | Internal Operations | HTTPS | No | 8.8 | Network | Low | Low | None | Un- changed |
High | High | High | 12.2.3-12.2.15 | |
| CVE-2026-46820 | Oracle Financials Common Modules | Common Components | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | Low | None | 12.2.3-12.2.15 | |
| CVE-2026-46828 | Oracle Payroll | Internal Operations | HTTP | No | 8.1 | Network | Low | Low | None | Un- changed |
High | High | None | 12.2.3-12.2.15 | |
| CVE-2026-46821 | Oracle Financials Common Modules | Common Components | HTTP | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.3-12.2.15 | |
| CVE-2026-46823 | Oracle Public Sector Financials (International) | Authorization | HTTPS | No | 7.7 | Network | Low | Low | None | Changed | High | None | None | 12.2.6-12.2.15 | |
| CVE-2026-46818 | Oracle Payments | File Transmission | HTTPS | Yes | 7.4 | Network | High | None | None | Un- changed |
High | High | None | 12.2.3-12.2.15 |
Oracle Hospitality Vulnerabilities:
| CVE ID | Product | Component | Protocol | Remote Exploit without Auth.? |
CVSS VERSION 3.1 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes |
|---|---|---|---|---|---|---|---|
| Base Score |
Attack Vector |
Attack Complex |
Privs Req’d |
User Interact |
Scope | Confid- entiality |
Inte- grity |
| CVE-2026-34311 | Oracle Hospitality OPERA 5 Property Services | Opera | HTTP | Yes | 9.8 | Network | Low | None | None | Un- changed |
High | High | High | 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, 5.6.28 | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
The May 28th 2026 Oracle Critical Security Patch Update Advisory:
https://www.oracle.com/security-alerts/cspumay2026.html
Actions
Identify any Oracle products in your network. Patch them immediately.
Notes
A matrix with more granular detail provided by Oracle
https://www.oracle.com/security-alerts/cspumay2026verbose.html
Oracle’s announcements that they are beginning a monthly patch schedule: